From addab6589fe8d0b44ba1d7a88134c740d971eb47 Mon Sep 17 00:00:00 2001 From: Tomasz Leman Date: Wed, 7 Oct 2026 13:50:19 +0200 Subject: [PATCH] probe: check dma_get_status() before using the status On the Zephyr native driver path the dma_status structure was read into dma->dmapb.avail and free_bytes before the return code was tested, so a failing dma_get_status() propagated uninitialized stack data into the probe buffer accounting. Move the error check directly after each call and only consume the status on success. Also correct the error trace format specifier from %u to %d. Found by clang-analyzer-core.uninitialized.Assign. Assisted-by: Copilot:claude-opus-5 clang-tidy Signed-off-by: Tomasz Leman --- src/probe/probe.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/src/probe/probe.c b/src/probe/probe.c index 8e312053551a..d3746ca05078 100644 --- a/src/probe/probe.c +++ b/src/probe/probe.c @@ -993,18 +993,22 @@ static void probe_cb_produce(void *arg, struct buffer_cb_transact *cb_data) struct dma_status stat; ret = dma_get_status(dma->dc.dmac->z_dev, dma->dc.chan->index, &stat); + if (ret < 0) { + tr_err(&pr_tr, "dma_get_status() failed, ret = %d", ret); + goto err; + } dma->dmapb.avail = stat.pending_length; free_bytes = stat.free; #else ret = dma_get_data_size_legacy(dma->dc.chan, &dma->dmapb.avail, &free_bytes); -#endif if (ret < 0) { - tr_err(&pr_tr, "dma_get_data_size() failed, ret = %u", + tr_err(&pr_tr, "dma_get_data_size() failed, ret = %d", ret); goto err; } +#endif /* check if transaction amount exceeds component buffer end addr */ /* if yes: divide copying into two stages, head and tail */